vendor:
Gelato CMS
by:
s0cratex
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Gelato CMS
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Gelato SQL Injection exploit
This is a SQL Injection exploit for Gelato CMS. It allows an attacker to retrieve usernames and MD5 hashes from the database by exploiting a vulnerability in the 'users' table.
Mitigation:
To mitigate this vulnerability, it is recommended to apply the latest patches and updates for Gelato CMS. Additionally, input validation and sanitization should be implemented to prevent SQL Injection attacks.